Reactions available for rule types

Prev Next

The available reactions for a rule vary depending on the rule type.

  • All data protection rules are available for Trellix DLP Endpoint - SaaS. Some data protection rules are available for Trellix DLP Network Prevent – SaaS and Trellix DLP Network Monitor – SaaS.

  • Trellix Device Control rules are available for Trellix DLP Endpoint - SaaS and Trellix Device Control.

  • Some discovery rules are available for Trellix DLP Endpoint - SaaS , some are available for Trellix DLP Discover – SaaS.

Rule reactions

Reaction

Applies to rules:

Result

No Action

All

Allows the action.

Block and return email to sender

Email Protection ( Trellix DLP Network Prevent – SaaS only)

Blocks the email message when there is a policy violation. The email is sent back to the sender as an attachment with a notification. You can customize the notification and specify as to why the email was sent back.

Add header X-RCIS-Action

Email Protection ( Trellix DLP Network Prevent – SaaS only)

Adds an action value to the X-RCIS-Action header.

Add Custom Header

Email Protection ( Trellix DLP Network Prevent – SaaS only)

Adds custom headers in the delivered email message. The custom header can report the number of rules and the cumulative score of all rules that violated a policy, or any other defined custom header.

Apply RM Policy

  • Data Protection

  • Removable Storage Protection

  • Network Discovery

Not supported on Trellix DLP Endpoint – SaaS for Mac

Applies a rights management (RM) policy to the file. The RM policy can be applied to Microsoft RMS on-premises and Azure RMS.

Block

  • Data Protection

  • Device Control

Blocks the action.

Classify file

  • Endpoint Discovery

  • Network Discovery

Applies automatic classifications and embeds the classification Tag ID into the file format.

Copy

Network Discovery

Copies the file to the specified UNC location.

Create Content Fingerprint

Endpoint Discovery

Applies content fingerprinting to the file.

Encrypt

  • Data Protection

  • Endpoint Discovery

Not supported on Trellix DLP Endpoint – SaaS for Mac.

Encrypts the file. Encryption options are Trellix FRP or StormShield Data Security encryption software.

Move

Network Discovery

Moves the file to the specified UNC location. Allows creation of a placeholder file (optional) to notify the user that the file has been moved. The placeholder file is specified by selecting a user notification definition.

Quarantine

Endpoint Discovery

Quarantines the file.

Read-only

Device Control

Forces read-only access.

Remove Automatic Classification

Network Discovery

Removes embedded classification ID from the file property.

Report Incident

All

Generates an incident entry of the violation in Data Protection Workspace.

Request justification

Data Protection

Produces a pop-up on the end-user computer. The user selects a justification (with optional user input) or selects an optional action.

Show file in DLP Endpoint console

Endpoint Discovery

Displays Filename and Path in the endpoint console. Filename is a link to open the file, except when the file is quarantined. Path opens the folder where the file is located.

Store original email as evidence

  • Data Protection

Not supported on Trellix DLP Endpoint – SaaS for Mac.

Stores the original message on the evidence share. Applies to Trellix DLP Endpoint - SaaS and Trellix DLP Network Prevent – SaaS email protection rules only.

Note

Requires a specified evidence folder and activation of the evidence copy service.

Store original file as evidence

  • Data Protection

  • Endpoint Discovery

  • Network Discovery

Saves the file for viewing through the Data Protection Workspace.

Note

Requires a specified evidence folder and activation of the evidence copy service.

User notification

  • Data Protection

  • Device Control

  • Endpoint Discovery

  • Web Protection for Prevent

Sends a message to the endpoint to notify the user of the policy violation.

Note

When User Notificationis selected, and multiple events are triggered, the pop-up message states: There are new DLP events in your DLP console, rather than displaying multiple messages.



Reconfigure action rules for web content.

You must reconfigure Trellix DLP Network Prevent – SaaS action rules for use on proxy servers.

Note

Proxy servers can only ALLOW or BLOCK web content.

Trellix DLP Network Prevent – SaaS data protection rule reactions

Rules

Reactions

No action

Apply RM Policy

Block

Encrypt

Report Incident

Request justification

Store original file (email) as evidence

User notification

Email protection

X

X

X

X

X

X

Web protection

X

X

X

X

X

X



Trellix DLP EndpointTrellix DLP Endpoint - SaaS data protection rule reactions

Rules

Reactions

No action

Apply RM Policy

Block

Encrypt

Report Incident

Request justification

Store original file (email) as evidence

User notification

Application File Access Protection

X

X

X

X

X

Clipboard protection

X

X

X

X

X

X

Cloud protection

X

X

X

X

X

X

X

X

Email protection

X

X

X

X

X

X

Network communication protection

X

X

X

X

X

Network share protection

X

X

X

X

X

X

Printer protection

X

X

X

X

X

X

Removable storage protection

X

X

X

X

X

X

X

X

Screen capture protection

X

X

X

X

X

Web protection

X

X

X

X

X

X



Device Control rule reactions

Rules

Reactions

No action

Block

Read-only

Citrix XenApp device

X

Fixed hard drive

X

X

X

Plug-and-play device

X

X

Removable storage device

X

X

X

Removable storage file access

X

X

TrueCrypt device

X

X

X



Trellix DLP Endpoint - SaaS discovery rule reactions

Rules

Reactions

No action

Encrypt

Apply RM policy

Quarantine

Create content fingerprint

Classify file

Endpoint file system

X

X

X

X

X

X

Endpoint mail storage protection

X

X

X



¹ File Server scans support copying and moving files only to SMB/CIFS shares.